Access Control Vulnerability in FreeScout Help Desk Software
CVE-2025-48473

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
29 May 2025

What is CVE-2025-48473?

FreeScout, a self-hosted help desk software, had a significant access control vulnerability prior to version 1.8.179. This flaw allowed users to create conversations from messages in other conversations without appropriate visibility checks. Consequently, unauthorized users could access arbitrary messages from different mailboxes or conversations they were not meant to view. The oversight stemmed from a lack of validation against the 'show_only_assigned_conversations' setting, which is intended to restrict access. This issue was addressed in version 1.8.179 to enhance security measures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

freescout < 1.8.179

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.